Skip to content

UI elements accessible through lock screen when app returns from background #733

@empewoow

Description

@empewoow

Bug description

On Android, when the Phoenix wallet is locked (showing "Unlock to continue" screen), UI elements from the underlying payment screen apparently remain interactive and can be triggered by tapping on their expected positions, even though they're not visible. In this case, I could open the "Add a custom description to this payment" pop-up. What else could be exploited by this issue..?

Steps to reproduce

  1. Open Phoenix wallet and create an invoice
  2. Share the invoice via another app, say a chat messaging app (this switches to another app)
  3. Return to Phoenix wallet later. The app will be locked showing "Unlock to continue"
  4. Tap in the middle area of the screen, slightly below the "Unlock to continue" text
  5. The "Add a custom description to this payment" popup appears, even though the app is locked

Environment

  • Phoenix version: 2.6.2
  • Android version: 15

Screenshot

I marked the location where I tapped in the screenshot:

Image

Metadata

Metadata

Assignees

Labels

UI-androidUser Interface issue in the Android app

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions